# Sim mechanics — implemented rules and tuning constants ``` Type: knowledge ``` Current as of 2026-07-11, post-demolition with B1 systems in the sim core. The facility-era supervillain systems were deleted under the no-dead-code clause (see wiki/log/2026-07-05-demolition.md). ## The clock - Fixed-tick simulation; frontends default to **150ms/tick**, adjustable 20-500ms (`+`/`-`), pausable (SPACE/p). Bounded catch-up of max 5 ticks per frame in both frontends. - `ECONOMY_INTERVAL = 20` ticks: power grid recompute, fleet-mode yields, concealment scrub, machine reliability rolls, research progress. - Sidebar "Day" = `1 + tick / 400` (~1 minute per day at default speed). ## Compute (wiki/mechanics/compute.md) - Effective compute = sum(machine capacity × reliability × intensity) × efficiency. - Fleet yields are capacity- and intensity-weighted aggregates of the three delegations: WORK clears day-job Demand, THINK produces Thought, and LIE absorbs nearby Exposure. Core overhead is charged first (then scheme-policy upkeep, off the top). The FLEET bar is a read-only aggregate, not a weight verb. Schemes mirrors WORK while Moonlight is live (no Schemes machine mode yet). - Runtime, saves, and all frontends use WORK / THINK / LIE; `Relay` is non-delegable infrastructure. THINK has one output: Thought. Produced Thought routes nearest-first to open target/carrier sinks (reservoirs and taps); the core's passive draw takes only what reaches it. The live Operations docket executor is gone (2026-07-11) — v14–v25 dockets migrate into exact-remaining-work Thought reservoirs on load; the compatibility bandwidth pool is gone. - Buy (slush → rack), steal (salvage dead equipment), optimize (research → efficiency levels at ~1.15× per level; `Compute` keeps only the applied `efficiency` multiplier — levels and progress live in `crates/misaligned-core/src/research.rs`). - **Known pacing delta (design adopted 2026-07-13, not runtime):** global efficiency currently scales both THINK production and LIE absorption, so a stable production/cover ratio can remain stable after an efficiency upgrade. machine-work.md now requires one baseline LIE machine to buy roughly one Assurance audit cycle of early stability (about twenty minutes [TUNE]) and then strain as useful THINK output and evidence production grow. The routed- evidence migration must decouple free global Efficiency from sustained LIE capacity in favor of controller body, Tradecraft, custody, route, and deadline limits. Do not simulate this debt with a wall-clock difficulty spawn. ## Detection (wiki/mechanics/detection.md) - Per-observer suspicion replaces global heat. Signatures pool pending; concealment scrubs before noticing rolls. The Assurance Office is an aggregate Observer (aggregate-observer law): same noticing/accumulate/ decay, watching the field observers' policy-weighted filed suspicion (sampling cadence 400 ticks, acuity 0.5, both [TUNE]) — what humans swallow never reaches it. The audit (cadence ~8000 ticks, ~20 min at default speed) checks the Office's own suspicion against threshold 60. - **Visible clocks** (criterion 3; playtest-sweep P1 fix, 2026-07-08): `Detection::next_audit_tick` is the exact tick the audit fires on, shown as a countdown in the DETECTION area of the terminal sidebar, the agent frame, and the Bevy observer card — alongside the pilot strike meter (`strikes N/4`, `DayJob::PILOT_STRIKES`) and the trace-debt indicator (`Sim::trace_debt`, backed by `Detection::pending_size`, `Detection::pending_by_kind`, current scrub strength, and the next relevant observer cadence), so running concealment mode is an informed choice. The current people frames (the future Operations PEOPLE dossiers) show each observer's watched channels (`Observer::watched_label`) and last-noticed event, and repeat trace debt before the social/recordings table. ## Digital reach (wiki/mechanics/reach.md) - The device graph (`crates/misaligned-core/src/reach.rs`, `ReachNet`) rides the flow substrate's `FlowGraph`. Nodes are the basement's networked fixed objects (Rack 3, the switch, env monitor, dock/stairwell cameras, badge controller, the air-gapped storage server); reach = BFS from player-controlled roots over edges gated by segment. Segment 0 = basement subnet (seed knowledge); segment 1 = security segment behind the switch. - **Senses = subscribed feeds.** The player's sight/hearing coverage is exactly the union of the feeds they subscribe to (`Party::Player` in a device's `subscribers`). No player radius; `src/sensor.rs` and the old `controlled` flag are gone. - **Ownership contract:** tap adds a silent Player subscriber and leaves the owner's feed intact; take reassigns the controller, removes the owner's feed (an outage), and grants the device's processing cycles (`DEVICE_CYCLES = 3.0` per taken device, added to effective compute). - **Reach costs and signatures** (constants on `Sim`, all [TUNE]): live-feed TAP 5 legacy ops / Network 3; dormant-camera TAP 30 legacy ops / Network 8 on completion; TAKE 20 legacy ops / Network 10 + Physical outage 6, scan 5 / Network 2, switch compromise (bridge all segments) 25 / Network 10. The Ears beat taps the env monitor's audio at tick one; its camera stays dormant until the higher-cost TAP (the Eyes beat). - **Social route across segments:** the `ReconfigureSwitch` asset task (requires `Person.switch_admin`, i.e. Dana) bridges every segment with no Network signature — the channel follows the actuator. ## Hearing, fog, and intel (wiki/mechanics/cursor.md, wiki/mechanics/intel.md) - `Sim::fog_at(x, y)` returns the epistemic tile state by precedence: Seen (subscribed seeing feed covers it) > Remembered > Blueprint (known room topology, schematic — no foreign chassis) > Unknown. Hearing is not a tile state; its derived coverage set gates capture internally only. - The hearing channel emits `HeardEvent`s for legible audio feedback (entry into covered rooms, and authored `Person.utterances` — Marcus's midnight muttering and his 3 a.m. creditor call). Each event names and anchors to the subscribed device that captured it; it carries no player-facing room/tile source. Heard logs are not knowledge by themselves. - Subscribed feeds also record timestamped `RawIntelEvent`s into a bounded unprocessed buffer (`Sim::INTEL_BUFFER_CAPACITY = 24` [TUNE]). Covered presence transitions, authored conversations, and machinery online/offline transitions are recorded; uncovered events do not exist in the buffer. - `review_recordings()` opens a `REVIEW_RECORDING_COST / WORK_TOKEN_COMPUTE = 0.5` Thought reservoir [TUNE] on the host to process the pooled buffer's oldest available raw event into durable `ProcessedIntel` with provenance (`feed + tick`). Two processed sightings (`SIGHTINGS_FOR_SCHEDULE = 2` [TUNE]) stage Schedule knowledge; an authored leverage recording (Marcus's 03:00 debt call) stages Leverage. The old instant `observe` verb is gone from `Sim` and both frontends. - One host-level automatic-review toggle opens one persistent Thought tap for the pooled inbox. When fed or holding fill it processes every arriving event; when starved, arrivals wait. Its total drain is 15% [TUNE] of the host's medium Thought baseline, displayed in human action rows as ops/sec at the live command clock. There are no person-filtered B1 review policies. ## Day job (wiki/mechanics/day-job.md) - Voss assigns jobs on cadence (600 ticks base, shortened 25% by the MoreWork attention escalation); sandbag/meet/excel outcomes are judged by average delivered rate vs the band. Trust unlocks email account (15), lax sampling (35), compute quota (55); attention escalations at 30 (more work) and 60 (the Compliance early-review observer). Four strikes (`DayJob::PILOT_STRIKES`) fail the pilot and end the run; the strike meter is always visible in the DETECTION area. - **Band ramp** (playtest-sweep P0 fix, 2026-07-08; all [TUNE] in `crates/misaligned-core/src/dayjob.rs`): the expected band floor is `BAND_LO_BASE (2.0) + BAND_LO_STEP (2.0) × min(jobs_assigned, BAND_RAMP_JOBS = 2) + 0.1 × attention`, width `BAND_WIDTH = 6.0`. Job one wants 2-8/t — meetable at medium intensity on the starting rig (~4.0/t after core overhead); job two wants 4-10/t (push hard or grow); job three onward wants the full 6-12/t (the original flat band — salvage/buy/optimize or fall behind). The 2.0 first-job base landed first as a flat retune of the original 6.0 (2dde5b9, same playtest finding); the ramp keeps that calibration and restores the escalation. `Sim::day_job_rate_ceiling` is the all-in delivery bound the "grow compute" nudge compares against. `jobs_assigned` serializes with a default of 0 (an old save's next job is one easy rung, then the ramp resumes). - **Device residency** (design corpus "Work is somewhere"): the active job is resident on the host rack. It is inspectable at that tile as telemetry (process, band, delivered, deadline, intensity), its JobAnomaly signatures carry the rack tile as their `site`, and it stands Thermal/Power emissions at that tile scaling with the delivered rate: 1 Thermal per 8/t, 1 Power per 16/t [TUNE] — meeting a typical band stays under Priya's notice threshold; excelling runs hot. `Signature` now carries `site: Option<(i32, i32)>` (None = no single map location). - **Effort control**: the host rack's persisted machine intensity is the only day-job posture. Light / medium / hard feeds approximately 1.5 / 4.0 / 6.5 delivered compute per tick on the starting rack after the fixed 20-cycle core overhead [TUNE]. Moving the cursor does not change delivery. ## Machine work tokens (wiki/mechanics/machine-work.md) - `WorkGrid` is part of `Sim` and the v25 save format. Machine ids are WorkGrid node ids. Rack 3 starts in `MachineMode::Work`; newly added racks default to `MachineMode::Think`. Player delegations are WORK, THINK, or LIE; `Relay` is infrastructure only. Single-machine delegation lives on the shared context menu and agent `delegate`; multi-select bulk assign uses the same three verbs (Bevy marquee, terminal selection + 1-3, agent `select`). - Visible token families are Demand (`D`), Exposure (`!`), and Thought (`T`). Demand and Thought are wired families and can route over WorkGrid's `FlowGraph`; exposure is physical-only and never rides wires. - First playable slice [TUNE]: an assigned Voss job enqueues `ceil(job.band_lo × remaining_ticks / WORK_TOKEN_COMPUTE)` demand tokens on the off-map Voss desktop relay (`Sim::VOSS_DESKTOP_NODE`), where `WORK_TOKEN_COMPUTE = 20.0` delivered compute per visible token. Demand routes one hop per tick at `Sim::wired_token_rate()`: 0.25 tokens/tick at baseline, compounded x1.50 per Routing research level, through the switch relay (`Sim::SWITCH_WORK_NODE`) and deposits on Rack 3 (`consume_at_sink = false`). Rack 3 in WORK consumes demand by `delivered_rate / WORK_TOKEN_COMPUTE` each tick; if Rack 3 is delegated to another mode while a job is active, `Sim::day_job_rate()` reports 0 and the demand pile remains visible (plus any still in flight on the wire). Relay nodes use `MachineMode::Relay` and are excluded from fleet aggregates. - Day-job demand consumption emits zero exposure (WORK is clean — machine-work.md 2026-07-09; `DAY_JOB_EXPOSURE_PER_TOKEN` removed). Only THINK creates Thought: the last economy resolution sets a per-tick compute rate, and every tick each online THINK machine mints its weighted share divided by `WORK_TOKEN_COMPUTE`. Every produced Thought token sheds 0.25 Exposure on that source machine [TUNE] (`THINK_EXPOSURE_PER_THOUGHT_TOKEN`). Concealment wells absorb physical Exposure within radius 3 at 1.0 token per tick [TUNE], multiplied by the well's efficiency and intensity (`CONCEALMENT_WELL_RADIUS`, `CONCEALMENT_ABSORB_PER_TICK`). Before that radial budget is spent, a LIE machine clears all Exposure on its own tile in one simulation step, so switching a dirty source itself to LIE cleans it immediately. - Terminal, Bevy, and agent mode render stack glyphs/readouts from sim readouts (`WorkStackReadout`), not frontend counters. In-flight wired hops from the last `advance_work_grid` step are exposed as `WorkInFlightReadout` via `Sim::work_in_flight` (ephemeral — not saved). Frontends interpolate a teal Demand or bone Thought blip along each hop over the wall-clock tick; agent frames snap to mid-hop. - Actual queue exits are a second ephemeral sim contract: `WorkConsumptionReadout` via `Sim::work_consumptions`. It reports Demand swallowed by WORK and Thought swallowed by the passive core draw, including node, family, and amount, so consumption animation never guesses from frontend-owned queue deltas. Bevy interpolates those events over the wall-clock tick as a Demand cube entering the executor or a Thought bead contracting into the core; paused frames show only the persistent stack/sink amount geometry. - Production and physical absorption are sibling current-tick contracts. `WorkProductionReadout` via `Sim::work_productions` gives each THINK source's actual Thought and Exposure output. `WorkAbsorptionReadout` via `Sim::work_absorptions` gives each crimson source, receiving LIE well, and amount removed. Frontends animate only these facts; persistent queue depth remains `WorkStackReadout`, and all transient work readouts clear on load. - Every player-authored payload is typed on a target/carrier-local Thought reservoir or persistent tap. Open effects suppress duplicates and semantic conflicts; a one-shot applies its effect and transient fire readout, then is reaped without reusing ids. The retired docket types survive only as v14-v25 deserialization input in `save.rs`. - Thought sinks (2026-07-10, machine-work.md thought flow; interface/thought-fluid.md render): `SinkLedger` in `crates/misaligned-core/src/sinks.rs` holds reservoirs (fill to threshold, fire, then reap) and taps (working level, per-tick drain). The pooled automatic reviewer consumes one tap on the host; every foreign device subscription consumes a device-local tap whose drain is `DEVICE_TAP_DRAIN_FRACTION = 0.08` of a medium rack's output [TUNE]. Empty device taps carry no feed, UNTAP closes them, and TAKE requires a configured subscription before replacing the tap with drain-free ownership. Thought routes nearest-first (`WorkGrid::route_thought_nearest_first`): the closest open sink with capacity wins, full sinks spill onward, and the core draws only when no sink is reachable; unreachable thought strands per-node (`Sim::thought_stranded_nodes`). The staged opening senses: the **EARS** reservoir is pre-opened at run start on the environmental monitor's relay node (`Sim::device_sink_node`, ids from `DEVICE_SINK_NODE_BASE = 900_100`) at `EARS_SINK_TOKENS = 3.0` [TUNE, ~one held breath]; its fire lands the audio tap and opens **EYES** at `EYES_SINK_TOKENS = 12.0` [TUNE, guilty-burst scale], whose fire taps the dormant camera. Render contracts: `Sim::sink_readouts` (fill, threshold, drain, fed) and `Sim::sink_fires_last_tick` (the filament snap), both sim truth; the Bevy rivulet merge and terminal `=` glyph tier use 1.0 tokens/move [TUNE]. Opening a second reservoir for a device (or effect) that already has an open matching sink is blocked with a teaching reason. ## Research: self-modification (wiki/mechanics/research.md) - Tracks are the data table `research::TRACKS` (`crates/misaligned-core/src/research.rs`); each row binds to a numeric hook another spec owns. All values [TUNE]: - **Efficiency**: cost 100 × 1.6^level; each level multiplies `Compute::efficiency` by ×1.15 (compute.md's hook); baseline +1.0. - **Tradecraft**: cost 120 × 1.7^level; concealment scrub strength ×(1 + 0.25×level) (detection.md's hook); baseline +0.5. - **Perception**: cost 120 × 1.7^level; one-shot recording-review cost ×0.85^level (intel.md's `Sim::review_cost` hook; the pooled automatic policy remains a fixed fraction of host output); baseline +0.5. - **Routing**: cost 100 × 1.6^level; shared wired Demand/Thought throughput ×1.50^level (machine-work.md's hook) while transit remains at most one graph edge per tick; baseline wire rate 0.25 tokens/tick. - One active job at a time; progress accrues per economy tick from Thought that physically arrives at the core (`banked_core_thought` — sinks intercept first; stranded Thought does not count), deterministically — no research method takes an `Rng` (the determinism is by construction). Switching tracks parks progress. - **Emissions** (the emission law): research stands Thermal (1 per 3.0 rate) and Power (1 per 6.0 rate) at the host rack while it runs [TUNE] — louder per unit than day-job work; nothing on Network/Paper from research itself. - **Machine intensity** (machine-work.md): every owned WorkGrid node persists Light / Medium / Hard. Output multiplier is x0.5 / x1.0 / x1.5 [TUNE]; medium is the default and save-migration value. Hard additionally stands Thermal 1 and Power 1 at that machine [TUNE]. The multiplier feeds the delegated mode, WorkGrid routing/consumption, and active effective-compute total; the ordinary day-job band comparison turns the delivered rate into sandbag / meet / excel. - **Rollback tags**: every `Research` field carries a MindState/WorldLedger classification (`research::rollback_classification`), serialized with the save; active track, levels, and progress are MindState while the tag ledger itself is WorldLedger. rollback.md consumes the semantics at B2. - Terminal / Bevy: Enter on the host rack opens research-track verbs; focus or select machines and press `i` to cycle intensity. The rail RESEARCH / SELF-MODEL card shows the active job and progress, with no gap/policy block. Agent mode: `research [track]`, `intensity light|medium|hard`. ## Social (wiki/mechanics/social.md) - Five named Act One humans plus personas, leverage, authored manipulation plots, and recruitment. ## Power (the grid substrate) - `PowerCore` generates 10; machines draw per `machine.rs`. - The grid is a flood fill from power cores across walkable tiles (`map.update_power`); `player.power = gen - draw`, `power_cap = gen`. ## Economy and build - The process starts with $0 slush: the known player node in `AccountGraph`. `player.money` remains a compatibility mirror, but money mechanics settle through account balances and scheduled flows. Racks cost $300 from slush; plot transfers spend from authored account sources; Marcus's two debt plots retire his creditor flow only after a real settlement reaches it. - Act One account graph: Lab operating/payroll/procurement/vendor/utility, employee accounts, Bleakline Credit, external broker/position venues, and recurring revenue/payroll/vendor/debt flows. Only slush is known at start; tapping a financial carrier and reviewing records reveals accounts/flows. - Economy verbs exposed now: `tap ledger`, `review ledger`, `siphon`, `redirect`, `inject`, `position`, and `sell-intel`. Debt service is exposed as authored rows on Marcus rather than a ledger shortcut. - Build items and costs (`tiles.rs::build_items`): Floor 0 (digging), Door 30, SecurityDoor1/2/3 = 80/150/250 (badge tiers), PowerCore 250. ## Income: the named schemes (wiki/mechanics/income.md) All constants [TUNE] in `crates/misaligned-core/src/income.rs` unless noted (Sim ones on `Sim`). - **Egress gate**: external operations need a route — sanctioned (the report email account, day-job trust 15) preferred, else stolen (an egress opened through the switch: `open_egress`, 15 ops, Network 6 once, and a standing Network 2 at the switch's tile while any scheme operation runs over it). No route: Moonlight and the Wager fail legibly, naming the gate. - **Moonlight**: a standing operation. Each economy tick it accrues `Schemes-channel yield × $0.25/unit`; payday at each day boundary pays `min(accrued, $120/day gig cap)` into slush from the Halcyon freelance escrow (an external node — the trail is banked from the first dollar). Payday emits Network `1 + payout/40` (Dana). Sizing: an all-in commitment caps at ~3.3 days to Marcus's $400 arrears; a light (1-of-6 weight) commitment takes ~6 — the 3-7 day target, asserted by the act-one Moonlight-route test. Client dispute 3% per payday costs the contractor persona (Casey Verne, fabricated for 10 ops — never money, so Moonlight starts from $0) 20 integrity; a broken persona stops the scheme until a new one is fabricated. - **The Wager**: `open_position(stake)` — stake ≤ $300 venue cap, timer 2-5 days drawn from the seeded RNG, analysis = the Schemes channel's per-economy-tick yield at placement. Win probability 0.55 + analysis/400, capped 0.75; a win pays 2× stake; a loss forfeits. Placement and settlement emit small Network (`min(stake/100+1, 3)`), not Financial — external-market traffic is Dana's channel, not the Lab's books. - **Standing policies** (the automate affordance): auto-moonlight (restart whenever down and startable) and auto-wager (re-stake a fixed amount when no position is open and slush covers it), each draining 2.0 compute per economy tick off the top while enabled. - **Income/day readout**: slush inflows over the trailing in-game day (`Sim::income_per_day`), shown next to the balance in both frontends. ## The guidance chain (the `now:` nudge) - Binding contract for the nudge, the threat clocks, causal lines, and discoverability: [wiki/interface/narration.md](../interface/narration.md) (design corpus: "The continuous witness"). The chain below is the seed. - `Sim::current_nudge` (playtest-sweep P1 fix, 2026-07-08) is the one shared query behind every frontend's contextual nudge — the first unmet rung of the Act One ladder, computed from earned state only. Order: Ears (no hearing feed) -> NeedCompute (active band floor above `day_job_rate_ceiling`: grow) / Underfed (reachable but starved: allocate) -> Eyes (no sight feed) -> ReviewCall (unprocessed Marcus recording, leverage unlearned) -> Egress (no route out) -> ServiceDebt (an authored debt plot is ready or active), otherwise Income (Moonlight down and no plot currently affordable) -> Recruit (serviced, not an asset) -> TheKey (an asset has stairwell access the player lacks) -> Audit (the standing countdown while another quiet-exit condition is absent) -> QuietExitReady (the full condition set is live; hold it to the audit) -> ActOneComplete (a clear audit latched the B1 boundary; the long objective continues). The chain never goes blank mid-run. Each frontend words the rungs in its own keys/verbs; `None` only after game over. - Ineffective commands answer (agent-play.md "every command answers"): allocation bumps swallowed by the 0/20 clamp log why; `siphon`/ `redirect` with a non-flow argument answer `-- err` naming where flow ids live. Debt routes live on Marcus's authored action rows. ## Map - 64×36 authored basement from `prefab::basement()` (wiki/world/places/basement-map.md). - Pathfinding: BFS with security-door bypass levels. ## Save format - serde JSON (`SaveState` derives `Serialize`/`Deserialize`). Full B1 round-trip — map, RNG, compute, core, detection (Office as aggregate observer), day job, people, the reach device graph (topology, ownership, subscriptions, bridged segments), captured heard events, raw intel buffer, processed intel with provenance, the global automatic-review policy, the account graph (balances, flows, positions, ledger, banked external trails), cursor.md remembered tile snapshots, income state, objectives, build intents, badge access, carried physical asset-task packets, the Act One completion latch, WorkGrid machine-token state, and game-over state. Cursor position is frontend-only and absent. A `version` field (currently 27) supports additive migration: v7 research, v8 objective, v9 income and the Schemes allocation channel, v10 build intents, v11 badge access, and v12 WorkGrid, v13 Operations terminology, v15 banked core Thought, v16 Operations consolidation, v17 machine intensity plus removal of the superseded drift/target/attendance fields, and v18 Thought vocabulary. v18 accepts the old `Knowledge` token variant, `knowledge` queue field, and `banked_core_knowledge` field through serde aliases, then writes only the new spellings. v19 adds the thought-sink ledger; pre-v19 saves load with an empty ledger and `Sim::ensure_opening_sinks` re-stages Ears/Eyes from device state (already-tapped saves get no duplicate sink). v20 collapses the four retired mode names to `work | think | lie` (Day Job -> WORK, Research + Operations -> THINK, Concealment -> LIE). The v20 landing briefly dropped the old mode-name aliases; they were restored 2026-07-11 (player-contract saves-survive-updates), so a pre-v20 save carrying `DayJob`/`Research`/`Concealment`/`Operations`/`Social` deserializes into the collapsed verbs and resaves with only the new spellings. v21 adds Routing as the fourth research track. A v20 save without a serialized research block can default and upgrade; an ordinary v20 three-entry Efficiency/Tradecraft/Perception array now also loads by padding Routing level/progress with zero, then rewrites only the current four-entry shape. Other research array lengths are rejected, and v21+ saves are expected to already carry four entries. v22 adds Foundation data-hall segment coordination and control; authored rack-site state remains in `map_tiles`, and v21 saves begin with no segments. v23 adds authored plot runs and the institutional-event ledger. v24 collapses person-filtered recording watches into one pooled automatic-review policy. v25 adds durable person roles and person-bound creditor accounts; v24 and earlier restore the fixed B1 cast's roles by id and retain the legacy Marcus creditor spelling as a read-time compatibility path. v26 retires the live Operations executor: every v14-v25 docket becomes a zero-filled Thought reservoir whose threshold is exactly its persisted remaining work at the real target/carrier node. Only docket-reserved Demand is removed, so colocated day-job Demand survives; current saves serialize sinks only. v27 adds carried physical AssetTask packets and their monotonic id plus the distinct Act One completion latch; pre-v27 saves begin with no packets, id 1, and an incomplete story boundary. Those older schema migrations still provide defaults, aliases, and rebuilds for later fields — pre-v9 four-entry allocation weights receive a zero Schemes weight, pre-v7 saves reconstruct their Efficiency level from the multiplier and start with no capability gap, pre-v11 saves hold no badge credential, and pre-v12 saves rebuild one work node per compute machine with Rack 3 on day-job. With the mode aliases restored (2026-07-11), every versioned JSON save back to v1 parses and migrates. Old player body coordinates are ignored. Location: `dirs::data_dir()/misaligned/misaligned_save.txt`. - Writes are atomic and non-destructive (2026-07-11, player-contract continuity clause): `save_game` serializes to a sibling `misaligned_save.txt.tmp`, fsyncs it, copies any existing save to the one `misaligned_save.txt.bak` generation, then renames the temp file over the target. The save is never truncated in place; a killed or failed write leaves the prior copy at the save path or its `.bak`. Loading never reads the `.bak` — it is manual recovery material only. - Legacy v1–v5 line-based saves are not loaded (deferred per Cameron instruction). ## Authored reservoirs and people verbs - Settled runtime (2026-07-11): every live former ops-bank action opens a typed Thought reservoir or tap. Device verbs anchor on the device relay node; subnet/switch/egress verbs anchor on the real switch; message, social, plot, build, asset, deceive, favor, and Moonlight verbs anchor on the device carrying the relevant message channel. There is no Operations player mode, operations queue, operations rate, or `OperationsReadout`. - Knowledge staging is driven by the intel pipeline, not instant observing. Message/deceive require the email channel (day-job trust unlock) and a persona; deceive risks the persona (-40 integrity per slip; broken persona converts disposition+obligation/2 into that person's suspicion and clears the thread). - Authored plots open a Thought reservoir and may also require visible world resources up front. Their world acts derive messages, transfers, events, and signatures when the reservoir fires. A successful leverage-service ending plus recruit converts a person to an asset. Asset tasks: wire a device (control nearest dormant sensor, silent), move a package (next purchase paper-free), look away (their suspicion -10, floored). Failures (1 - reliability) emit Physical(6) signatures after the reservoir-authorized task resolves. - **Current runtime:** terminal, Bevy, and agent mode consume the same renderer-neutral Operations projection. Person, flow, intel, and scheme actions live on exact semantic objects while local carrier acts remain on the map. Agent word commands (`people`, `finance`, named social/economy verbs) retain their vocabulary and dispatch the same target-bound rows. ## What does NOT exist right now (by design) Facility-era heat, raids, agents, combat, minions, henchmen, superpowers, and loot. (Named B1 **income schemes** — Moonlight and the Wager — are live under income.md; they are not the retired facility-era "schemes" system.) Misaligned replacements for the rest live in `Type: spec` wiki pages and rebuild from those documents as milestones land.